ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 2. ISO 27001 Annex A Cont...
  5. ISO 27001 Annex A 5.9 Inventory of information and other associated assets

ISO 27001 Annex A 5.9 Inventory of information and other associated assets

ISO 27001 Annex A 5.9 focuses on maintaining an inventory of information and other assets that are associated with information processing.

The purpose is to help the organization understand:

  • What information it owns or manages
  • What systems process that information
  • What devices and technology support those systems
  • Who is responsible for the assets
  • Where important information and assets are located
  • Which assets are critical to the business
  • What needs to be protected

Simple explanation

A.5.9 means an organization should know what information and technology assets it has, where they are, who is responsible for them, and what needs to be protected.

You cannot effectively protect assets that you do not know exist.

For example, if a company does not know that an employee has created a production database outside the approved environment, the organization may not be able to properly secure or monitor it.


Why is A.5.9 important?

Modern organizations may have hundreds or thousands of assets.

These may include:

  • Laptops
  • Servers
  • Cloud resources
  • Databases
  • Applications
  • Source-code repositories
  • SaaS applications
  • Mobile devices
  • Network equipment
  • APIs
  • Digital documents
  • Customer information
  • Employee information
  • Credentials and secrets
  • Backup systems

Without an accurate inventory, organizations may:

  • Forget to patch systems
  • Leave accounts active
  • Miss vulnerabilities
  • Lose track of sensitive information
  • Fail to apply appropriate security controls
  • Have difficulty responding to incidents
  • Lose track of third-party services
  • Fail to meet customer or regulatory requirements

Simple principle

Know what you have before you try to protect it.


What does A.5.9 require?

The organization should establish and maintain an inventory of information and other associated assets.

The inventory should be:

  • Appropriate to the organization’s environment
  • Maintained and updated
  • Assigned to responsible owners
  • Relevant to information security
  • Available to appropriate personnel

The exact format is not prescribed.

An organization may use:

  • Spreadsheet
  • CMDB
  • Asset-management software
  • GRC platform
  • Cloud inventory
  • IT management platform
  • Configuration-management database

The important point is that the organization can demonstrate that relevant assets are identified and managed.


What is an Information Asset?

Information assets include information that has value to the organization.

Examples:

Business information

  • Business plans
  • Contracts
  • Financial information
  • Management reports
  • Intellectual property

Customer information

  • Customer records
  • Customer contracts
  • Customer support information
  • Customer data

Personal information

  • Employee information
  • Customer personal data
  • Contact information
  • Identification information

Security information

  • Security logs
  • Vulnerability reports
  • Incident records
  • Risk assessments
  • Security configurations

Technical information

  • Source code
  • API documentation
  • Architecture diagrams
  • Configuration files
  • Technical documentation

What are Associated Assets?

Associated assets are assets that support information processing.

Examples include:

Hardware

  • Laptops
  • Desktops
  • Servers
  • Mobile devices
  • Network devices

Software

  • Operating systems
  • Applications
  • Databases
  • Development tools
  • Security tools

Cloud

  • AWS accounts
  • Azure subscriptions
  • GCP projects
  • Cloud databases
  • Storage buckets
  • Virtual machines
  • Containers

Applications and services

  • CRM
  • HRMS
  • ERP
  • Ticketing systems
  • Collaboration platforms
  • SaaS applications

Network and infrastructure

  • Firewalls
  • Routers
  • Switches
  • VPN
  • DNS
  • Load balancers

Digital repositories

  • GitHub repositories
  • Document storage
  • Shared drives
  • Backup systems

Activities required to implement A.5.9

1. Identify information assets

Start by identifying important information used by the organization.

For example:

Information AssetExample
Customer InformationCustomer account data
Employee InformationHR records
Financial InformationInvoices and financial records
Source CodeGitHub repositories
Security InformationIncident reports
Business InformationContracts
Product InformationProduct documentation

2. Identify associated technology assets

Next identify the systems and technology used to create, store, process or transmit that information.

Example

Customer Information

↓

Stored in:

Production Database

↓

Hosted on:

AWS

↓

Accessed through:

Customer Application

↓

Managed by:

Engineering Team

This relationship helps the organization understand what needs to be protected.


3. Assign an owner

Each important asset should have an appropriate owner.

The owner does not necessarily need to operate the asset.

The owner is responsible for ensuring that appropriate security requirements are applied.

For example:

AssetOwner
Customer DatabaseCTO
HR InformationHR Manager
Financial InformationCFO
Source CodeEngineering Lead
AWS EnvironmentCloud/IT Lead
Security LogsSecurity Lead

For a startup, one person may own multiple assets.


4. Classify information

The organization should classify information according to its sensitivity and business value.

For example:

Public

Information intended for public release.

Examples:

  • Website content
  • Marketing material
  • Public documentation

Internal

Information intended for employees or authorized personnel.

Examples:

  • Internal procedures
  • Internal announcements
  • Operational documentation

Confidential

Information that could cause harm if disclosed without authorization.

Examples:

  • Customer contracts
  • Business plans
  • Internal financial information

Restricted

Highly sensitive information requiring stronger protection.

Examples:

  • Credentials
  • Encryption keys
  • Sensitive personal information
  • Critical security information

The organization’s classification scheme can be simpler or more detailed depending on its needs.


5. Record important asset attributes

The inventory should contain information that is useful for managing security.

Depending on the organization, this may include:

  • Asset name
  • Asset type
  • Owner
  • Location
  • Business purpose
  • Classification
  • Criticality
  • System/environment
  • Responsible department
  • Vendor
  • Lifecycle status
  • Associated information
  • Access requirements

Not every field is required for every organization.

The inventory should be practical and useful.


6. Identify critical assets

Not every asset has the same importance.

The organization should identify assets that are critical to:

  • Business operations
  • Customer services
  • Security
  • Regulatory compliance
  • Revenue generation
  • Confidential information

Example

For a SaaS company:

Production Database → Critical

Production Application → Critical

Source Code Repository → High

Corporate Website → Medium

Marketing Presentation → Low

This can help prioritize security efforts.


7. Include cloud assets

Modern organizations often have significant assets in cloud environments.

The inventory may include:

  • Cloud accounts
  • Subscriptions
  • Projects
  • Virtual machines
  • Databases
  • Storage
  • Containers
  • Kubernetes clusters
  • Serverless functions
  • API gateways
  • Security services

Example

A startup may maintain:

Cloud AssetEnvironmentOwnerCriticality
AWS Production AccountProductionCTOCritical
PostgreSQL DatabaseProductionEngineeringCritical
S3 StorageProductionEngineeringHigh
Development AccountDevelopmentEngineeringMedium

8. Include SaaS applications

SaaS applications are frequently forgotten in asset inventories.

Examples:

  • Microsoft 365
  • Google Workspace
  • Slack
  • Jira
  • GitHub
  • Salesforce
  • HubSpot
  • Zoom
  • HR platforms
  • Accounting platforms

The organization should understand:

  • Who owns the application?
  • What information does it contain?
  • Who can access it?
  • Is sensitive information stored there?
  • What security requirements apply?

9. Keep the inventory updated

An inventory that is created once and never updated will quickly become inaccurate.

The organization should establish events that trigger updates.

Examples:

  • New application
  • New cloud environment
  • New employee
  • New laptop
  • New SaaS provider
  • System retirement
  • Business acquisition
  • Major technology change
  • New database
  • New production environment

10. Periodically review the inventory

The organization should periodically confirm:

  • Assets still exist
  • Owners are correct
  • Classification remains appropriate
  • Criticality remains appropriate
  • Retired assets are removed
  • New assets are included
  • Unauthorized assets are investigated

The frequency should be based on the organization’s environment and risk.


Startup Example

Consider a SaaS startup with 50 employees.

The company uses:

  • AWS
  • GitHub
  • Google Workspace
  • Slack
  • Jira
  • PostgreSQL
  • Microsoft 365 for some business functions
  • Several third-party SaaS applications

A simple asset inventory could look like:

AssetTypeOwnerClassificationCriticality
AWS ProductionCloudCTOConfidentialCritical
Customer DatabaseInformation/DatabaseCTORestrictedCritical
GitHub OrganizationSaaS/RepositoryEngineering LeadConfidentialCritical
Google WorkspaceSaaSIT LeadConfidentialHigh
JiraSaaSEngineeringInternalHigh
Employee LaptopsHardwareITConfidentialHigh
Corporate WebsiteApplicationMarketing/ITPublicMedium

This gives the organization a practical picture of its environment.


Asset Lifecycle

Assets should be managed throughout their lifecycle.

1. Acquisition

New asset identified

↓

2. Registration

Added to inventory

↓

3. Ownership

Owner assigned

↓

4. Classification

Information sensitivity determined

↓

5. Protection

Security controls applied

↓

6. Review

Asset periodically reviewed

↓

7. Retirement

Asset removed or securely decommissioned

↓

8. Inventory Update

Status updated


Example Asset Inventory

Asset IDAsset NameTypeOwnerLocationClassificationCriticalityStatus
AST-001AWS ProductionCloudCTOAWSConfidentialCriticalActive
AST-002Customer DBDatabaseCTOAWSRestrictedCriticalActive
AST-003GitHubSaaSEngineeringCloudConfidentialCriticalActive
AST-004Employee LaptopHardwareITEmployeeConfidentialHighActive
AST-005Corporate WebsiteApplicationMarketingCloudPublicMediumActive

The exact fields should be customized to the organization.


A.5.9 Audit Evidence

An auditor may look for evidence such as:

Information inventory

  • Information asset register
  • Data inventory
  • Data classification records
  • Data-flow diagrams

Technology inventory

  • Hardware inventory
  • Software inventory
  • Application inventory
  • Cloud asset inventory
  • Network inventory

Ownership

  • Asset owners
  • Responsible departments
  • RACI documentation

Lifecycle evidence

  • Asset onboarding records
  • Asset changes
  • Asset retirement records
  • Disposal records

Review evidence

  • Periodic inventory review
  • Reconciliation reports
  • Asset-management reports
  • Owner confirmation

A.5.9 Audit Checklist

Audit QuestionEvidence
Has the organization identified relevant information assets?Information Asset Register
Has it identified associated technology assets?Asset Inventory
Is an owner assigned to important assets?Asset Register
Is information appropriately classified?Classification Records
Are critical assets identified?Criticality Assessment
Are cloud assets included?Cloud Inventory
Are SaaS applications included?SaaS Register
Are asset locations identified?Asset Register
Is the inventory periodically reviewed?Review Records
Are retired assets removed from the inventory?Decommissioning Records
Are unauthorized or unknown assets investigated?Security / IT Records
Is the inventory updated when new assets are introduced?Change / Onboarding Records

Common Mistakes

1. Maintaining only a laptop inventory

A.5.9 is much broader than an employee hardware list.

The organization should consider:

Information + Applications + Cloud + Infrastructure + Devices + Services


2. Forgetting SaaS applications

Employees may use dozens of cloud services.

Unknown SaaS applications can create security and compliance risks.


3. No asset ownership

An inventory should not simply say:

“AWS Production – Active.”

It should identify an appropriate owner.


4. Creating the inventory only for the audit

A spreadsheet created one week before the audit may quickly become outdated.

The inventory should be part of normal operational processes.


5. Not updating retired assets

Old systems, applications and accounts should not remain listed as active indefinitely.


6. Treating every asset equally

Critical production systems and public marketing documents do not require the same level of protection.

Asset criticality and information classification help prioritize security controls.


Practical Startup Implementation

A startup can implement A.5.9 without buying an expensive asset-management platform.

Start with five categories:

1. Information

Customer data, employee data, financial data, source code.

2. Applications

Production applications, internal applications and SaaS applications.

3. Cloud

AWS, Azure, GCP and associated resources.

4. Hardware

Laptops, servers and network equipment.

5. Third Parties

Important suppliers and services that process organizational information.

Then assign:

Owner → Classification → Criticality → Location → Status


Simple Rule

If you don’t know an asset exists, you cannot reliably assess its risk, protect it, monitor it or retire it.


Policy vs. Process vs. Evidence

ElementExample
PolicyThe organization shall maintain an inventory of information and associated assets relevant to information security.
ProcessAssets are identified, assigned to owners, classified, recorded, periodically reviewed and updated throughout their lifecycle.
EvidenceAsset register, cloud inventory, application inventory, ownership records, classification records and periodic review evidence.

The objective is not to create a massive spreadsheet.

The objective is to maintain a reliable picture of the organization’s information and technology environment.


Useful Resources

Recommended documents

  • Information & Asset Inventory Template – [Insert Draft Document Link]
  • Asset Classification Procedure – [Insert Draft Document Link]
  • Asset Ownership Register – [Insert Draft Document Link]
  • Cloud Asset Inventory – [Insert Draft Document Link]
  • SaaS Application Register – [Insert Draft Document Link]
  • Asset Lifecycle Management Procedure – [Insert Draft Document Link]
  • Data Inventory Template – [Insert Draft Document Link]

Related ISO 27001 controls

A.5.9 can work closely with:

  • A.5.1 – Policies for information security
  • A.5.2 – Information security roles and responsibilities
  • A.5.10 – Acceptable use of information and other associated assets
  • A.5.11 – Return of assets
  • A.5.12 – Classification of information
  • A.5.13 – Labelling of information
  • A.5.23 – Information security for use of cloud services
  • A.7.9 – Security of assets off-premises
  • A.8.1 – User endpoint devices
  • A.8.9 – Configuration management
  • A.8.10 – Information deletion

Final Takeaway

ISO 27001 Annex A 5.9 is about knowing what information and technology assets the organization has and ensuring they are properly identified, owned and managed.

A practical organization should be able to answer:

What information do we have?
Where is it stored?
Which systems process it?
Who owns those assets?
How sensitive or critical are they?
Are new and retired assets being tracked?

For startups, the approach can remain simple:

Identify → Register → Assign Owner → Classify → Assess Criticality → Protect → Review → Retire

The goal is not to maintain an inventory for the sake of ISO certification.

The goal is to ensure that the organization has a clear and current understanding of what it needs to protect.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *